<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ¿How to use user-roles in Ironport WSA (7.6) using ACS 4.1? in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442464#M4483</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I want to give a client access to a S370 WSA quarantine and I am using an ACS 4.1 for external authentication; that would be used for administrators and for the client access (non-administration access).&lt;/P&gt;&lt;P&gt;I have created a user-role in the WSA that has access to the quarantine I want, but I need the user to be in the ACS. I created the user in ACS but my question is, what should I configure or change in the ACS in order for the WSA to recognize the user with the specific role I created and not like an administrator role.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Sergio&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2014 19:31:52 GMT</pubDate>
    <dc:creator>slizarraga</dc:creator>
    <dc:date>2014-04-21T19:31:52Z</dc:date>
    <item>
      <title>¿How to use user-roles in Ironport WSA (7.6) using ACS 4.1?</title>
      <link>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442464#M4483</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I want to give a client access to a S370 WSA quarantine and I am using an ACS 4.1 for external authentication; that would be used for administrators and for the client access (non-administration access).&lt;/P&gt;&lt;P&gt;I have created a user-role in the WSA that has access to the quarantine I want, but I need the user to be in the ACS. I created the user in ACS but my question is, what should I configure or change in the ACS in order for the WSA to recognize the user with the specific role I created and not like an administrator role.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Sergio&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2014 19:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442464#M4483</guid>
      <dc:creator>slizarraga</dc:creator>
      <dc:date>2014-04-21T19:31:52Z</dc:date>
    </item>
    <item>
      <title>Hi, This can be done by</title>
      <link>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442465#M4484</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can be done by configuring the Radius Class attribute on the ACS and mapping it with the user roles on the WSA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"To map RADIUS users to different Web Security appliance user role types, you assign a role type, such&lt;BR /&gt;as Administrator and Operator, to a RADIUS CLASS attribute. Mapping different role types lets you&lt;BR /&gt;specify the authorization level for each RADIUS user."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please go to Page 26-12 of the WSA user guide&amp;nbsp;http://www.cisco.com/c/dam/en/us/td/docs/security/wsa/wsa7-5/user_guide/WSA_7-5-0_UserGuide.pdf for more information under the section "Using External Authentication".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kush&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 07:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442465#M4484</guid>
      <dc:creator>kushsriva</dc:creator>
      <dc:date>2014-04-22T07:05:09Z</dc:date>
    </item>
    <item>
      <title>Thanks kushsriva !The</title>
      <link>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442466#M4485</link>
      <description>&lt;P&gt;Thanks &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/kushsriva" title="View user profile."&gt;kushsriva&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; !&lt;BR /&gt;&lt;BR /&gt;The document was for the WSA but it was usefull anyway. The class attribute in Radius uses number 25&amp;nbsp; and in the Cisco ACS is indicated like this:&lt;BR /&gt;&lt;BR /&gt;ou=definedclass&lt;BR /&gt;&lt;BR /&gt;In the ESA I had to make a modification ("Map externally authenticated users to multiple local roles".&lt;BR /&gt;&lt;BR /&gt;Thanks again &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/kushsriva" title="View user profile."&gt;kushsriva&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;!!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 22:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-to-use-user-roles-in-ironport-wsa-7-6-using-acs-4-1/m-p/2442466#M4485</guid>
      <dc:creator>slizarraga</dc:creator>
      <dc:date>2014-04-22T22:48:30Z</dc:date>
    </item>
  </channel>
</rss>

